Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci(deps): update GitHub Actions #115

Merged
merged 1 commit into from
Oct 7, 2023
Merged

ci(deps): update GitHub Actions #115

merged 1 commit into from
Oct 7, 2023

Conversation

bfra-me[bot]
Copy link
Contributor

@bfra-me bfra-me bot commented Oct 7, 2023

This PR contains the following updates:

Package Type Update Change
ossf/scorecard-action action minor v2.0.6 -> v2.3.0
step-security/harden-runner action minor v2 -> v2.6.0

Release Notes

ossf/scorecard-action (ossf/scorecard-action)

v2.3.0

Compare Source

What's Changed

Documentation

New Contributors

Full Changelog: ossf/scorecard-action@v2.2.0...v2.3.0

v2.2.0

Compare Source

What's Changed

Scorecard Result Viewer

Thanks to contributions from @​cynthia-sg and @​tegioz at CLOMonitor, there is a new Scorecard Result visualization page at https://securityscorecards.dev/viewer/?uri=<project-url>.

As an example, you can see our own score visualized here
Checkout our README to learn how to link your README badge to the new visualization page.

Publishing Results

This release contains two fixes which will improve the user experience when publish_results is true

Docs

New Contributors

Full Changelog: ossf/scorecard-action@v2.1.3...v2.2.0

v2.1.3

Compare Source

What's Changed

Bug Fixes
  • Invalid SARIF files from a bug in scorecard
  • Vulnerabilities check crashes if a vulnerable dependency is found via OSVScanner
  • Scorecard action not reporting binary artifacts in the repo

Full Scorecard Changelog: ossf/scorecard@v4.10.2...v4.10.5

Full Changelog: ossf/scorecard-action@v2.1.2...v2.1.3

v2.1.2

Compare Source

What's Changed

Fixes

Full Changelog: ossf/scorecard-action@v2.1.1...v2.1.2

v2.1.1

Compare Source

Scorecard version

This release use Scorecard's v4.10.1

Full Changelog: ossf/scorecard-action@v2.1.0...v2.1.1

v2.1.0

Compare Source

What's Changed

Scorecard version

This release uses scorecard v4.10.0.

Improvements
Documentation

New Contributors

Full Changelog: ossf/scorecard-action@v2.0.6...v2.1.0

step-security/harden-runner (step-security/harden-runner)

v2.6.0

Compare Source

What's Changed

Release v2.6.0 by @​varunsh-coder in https://github.com/step-security/harden-runner/pull/346

This release adds support for self-hosted Virtual Machine runners (e.g. on EC2).

Full Changelog: step-security/harden-runner@v2...v2.6.0

v2.5.1

Compare Source

What's Changed

Full Changelog: step-security/harden-runner@v2...v2.5.1

v2.5.0

Compare Source

What's Changed

Release v2.5.0 by @​h0x0er and @​varunsh-coder in https://github.com/step-security/harden-runner/pull/325

This release:

  1. Adds support for Actions Runner Controller (ARC) environment
  2. Improves the job summary markdown

Full Changelog: step-security/harden-runner@v2...v2.5.0

v2.4.1

Compare Source

What's Changed

Release v2.4.1 by @​varunsh-coder and @​Devils-Knight in https://github.com/step-security/harden-runner/pull/309

This release

  1. Shows a preview of the network events in the job summary markdown
  2. Uses a fallback DNS service from Cloudflare in addition to Google DNS to improve reliability

Full Changelog: step-security/harden-runner@v2...v2.4.1

v2.4.0

Compare Source

What's Changed

Full Changelog: step-security/harden-runner@v2...v2.4.0

v2.3.1

Compare Source

What's Changed

Full Changelog: step-security/harden-runner@v2...v2.3.1

v2.3.0

Compare Source

What's Changed

Full Changelog: step-security/harden-runner@v2...v2.3.0

v2.2.1

Compare Source

What's Changed

Full Changelog: step-security/harden-runner@v2...v2.2.1

v2.2.0

Compare Source

v2.1.0

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@bfra-me bfra-me bot requested a review from a team as a code owner October 7, 2023 18:22
@bfra-me bfra-me bot added automerge dependencies Dependency updates or security alerts labels Oct 7, 2023
@bfra-me bfra-me bot enabled auto-merge (squash) October 7, 2023 18:22
@bfra-me bfra-me bot force-pushed the renovate/github-actions branch from 2a76203 to 614ccca Compare October 7, 2023 18:23
@bfra-me bfra-me bot force-pushed the renovate/github-actions branch from 614ccca to 282919e Compare October 7, 2023 19:14
@bfra-me bfra-me bot merged commit b7e7cb5 into main Oct 7, 2023
8 checks passed
@bfra-me bfra-me bot deleted the renovate/github-actions branch October 7, 2023 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Dependency updates or security alerts
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants